Exercise
Fix SELinux Label on about.html File Exercise
Task
Give about.html the label the policy
expects, confirm Apache serves it, and see what a copy
would have done differently.
- Host
workstation- Prerequisite
- Add New Web Page Exercise
-
Inspect the policy for /var/www
sudo semanage fcontext -l | grep '/var/www' | head -n5 -
Apply the policy to /var/www recursively
sudo restorecon -Rv /var/www ls -lZ /var/www/html/restoreconreports each file it relabels.about.htmlchanges fromuser_tmp_ttohttpd_sys_content_t. -
Verify access to about.html
getenforce curl http://localhost/about.htmlWith SELinux enforcing, you should see
<h1>About Us</h1>. -
Test cp vs mv
What if the page had been copied instead of moved?
echo '<h1>About Us - Again</h1>' > /tmp/about2.html ls -lZ /tmp/about2.html sudo cp /tmp/about2.html /var/www/html/about2.html ls -lZ /var/www/html/about2.html curl http://localhost/about2.html -
Clean up the test pages
sudo rm -f /var/www/html/about.html /var/www/html/about2.html /tmp/about2.html ls -lZ /var/www/html/